Back to Feed
RansomwareSep 30, 2026

Global Group Ransomware Abuses WinMerge to Deploy Encryptor

Global Group ransomware uses WinMerge to deploy encryptor via payment-themed phishing.

Summary

Researchers at Cofense have uncovered a new tactic employed by the threat group Global Group. They are leveraging payment-themed phishing emails containing malicious ISO files that, when opened, utilize the legitimate WinMerge software to deploy their ransomware encryptor. This method targets large enterprises, aiming to extort them through ransomware attacks.

Indicators of Compromise

  • malware — Global Group ransomware

Entities

Global Group (threat_actor)WinMerge (product)